Redirect Vulnerability in IBM Security Access Manager
CVE-2017-1489

6.1MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
23 August 2017

Summary

A redirect vulnerability exists in the e-community configurations of IBM Security Access Manager versions 6.1, 7.0, 8.0, and 9.0. This flaw allows the ECSSO Master Authentication to redirect users to an external server that is not part of the e-community domain. Such unauthorized redirection can pose significant security risks by potentially exposing sensitive user information to attackers who control the rogue servers. Proper security measures and updates are essential to mitigate this risk.

Affected Version(s)

Security Access Manager for Web 6.1

Security Access Manager for Web 6.1.1

Security Access Manager for Web 7.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.